Keep review obligations visible and reconcile owner evidence (RISK-WP-0006, RISK-WP-0007)

check_all runs every check stage even when one fails; malformed dates are
reported rather than aborting; accepted findings and closure evidence are
shown; defer requires a valid future date. Adds SCOPE.md, the scope
assessment, the open-findings source review and a unittest suite. Stops
tracking __pycache__.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 6903@bnt-lap001
Assistant-Session: 8319e8a8-ffa6-4eb3-b8bf-b29945628f89
This commit is contained in:
tegwick 2026-09-22 07:56:58 +02:00
parent 29f50d5143
commit bbbede5f47
25 changed files with 1007 additions and 43 deletions

View file

@ -12,7 +12,9 @@ date_filed: "2026-08-23"
system: railiance-platform
environment: production
fix_owner: railiance-platform
fix_tracking: unset
fix_tracking: RPF-WP-0029-T02
closure_condition: "provider invalidation plus governed ciphertext upload and restore receipts; source fallback removal alone does not lift the embargo"
verification: RISK-V-0003
# Graded by risk-nexus 2026-09-01 — docs/rulings/2026-09-01-inbox-sweep.md
severity: low
severity_at_production: low
@ -25,20 +27,20 @@ embargo_condition: "the provider credential is revoked or invalidated and the li
embargo_since: "2026-09-01"
embargo_review: "2026-09-15"
escalation: none
last_checked: "2026-09-02T08:11:17Z"
next_check: "2026-09-02T09:11:17Z"
cadence: 1h
clean_streak: 1
last_checked: "2026-09-05T00:05:51Z"
next_check: "2026-09-05T00:05:51Z"
cadence: instant
clean_streak: 0
waiting_on:
- who: railiance-platform
what: "revoke or invalidate the provider credential, remove the source default, name fix tracking, and demonstrate governed ciphertext upload plus restore"
what: "complete RPF-WP-0029-T02: revoke or invalidate the provider credential and demonstrate governed ciphertext upload plus restore; source fallback removal is established"
since: "2026-09-01"
would_change: "the finding becomes fixed and the embargo lifts"
default: "the low grade and embargo stand; missing fix tracking is recorded as a stalled remediation"
default: "the low grade and embargo stand; absent provider invalidation and recovery evidence is recorded as a stalled remediation"
default_at: "2026-09-15"
graded_by: risk-nexus
ruling: RISK-RULING-2026-09-01-A
checked_by: "grok/risk-nexus"
checked_by: "codex/risk-nexus"
---
# RISK-F-0010 — Forgejo backup source embeds a WebDAV credential default
@ -118,7 +120,21 @@ does not soften the assessment.
Reasoning: `docs/rulings/2026-09-01-inbox-sweep.md`.
## Source remediation reconciled — 2026-09-05
RPF-WP-0029-T01 records source fallback removal and fail-closed input checks.
This register confirmed the named fallback is absent in the current script
without displaying or testing any credential. RPF-WP-0029-T02 remains `wait`
for provider invalidation and governed encrypted upload/restore receipts.
[RISK-V-0003](../docs/verifications/2026-09-05-open-findings-source-review.md)
records the boundary: source removal does not establish invalidation of the
predecessor. Open, low, embargoed and no escalation remain appropriate on the
available evidence. The 2026-09-15 review/default is unchanged. The historical
source-default statements above describe the earlier assessments.
## Reviews
- **2026-09-01** — graded from the filed report and a redacted current-source check. The literal default remains; no fix record was found. Cadence starts at instant.
- **2026-09-02** — clean check: literal source default remains; no fix tracking; embargo and 2026-09-15 wait unchanged. Cadence instant → 1h (1 clean in a row); next check 2026-09-02 09:11Z.
- **2026-09-05** — not clean: Confirmed source fallback removal and RPF-WP-0029 tracking; provider invalidation and encrypted upload/restore receipts remain pending. Low grade and embargo retained; see RISK-V-0003. Cadence 1h → instant; checked again immediately.